LIVE: New phishing campaigns targeting mobile users —View latest threats →

Back to Threats
Critical🎭 Social Engineering

Business Email Compromise (BEC) / CEO Fraud

BEC / CEO fraud tricks employees into urgent wire transfers by spoofing executive email. It caused $2.9B in losses in 2023 — the #1 cybercrime threat.

Published: 15 January 2026Last updated: 5 March 2026

What Is This Threat?

Business Email Compromise (BEC) is a sophisticated scam targeting companies that regularly perform wire transfers. Attackers either compromise a real executive's email account or spoof it convincingly, then instruct employees in finance or HR to send money to fraudulent accounts — all under the guise of an urgent, confidential business need.

The FBI IC3's 2023 report ranked BEC as the #1 cybercrime by total financial loss, with $2.9 billion stolen from businesses globally. In Europe, ENISA identifies it as a top-priority threat for organizations of all sizes.

How It Works

Variant 1 — CEO Wire Transfer Fraud:

  • Attackers research the company on LinkedIn and its website: who is the CEO, who handles finances, what projects are underway.
  • They send an email appearing to come from the CEO (spoofed address or compromised mailbox) to the CFO or finance manager: "I need you to process a confidential wire transfer of €85,000 to close a deal today. Do not discuss this with anyone — I'll explain after. Please confirm when done."
  • The urgency and secrecy prevent the employee from verifying. By the time the fraud is discovered, the money has been withdrawn.
  • Variant 2 — Fake Invoice Fraud:

    Attackers compromise a supplier's email, wait to see an ongoing invoice thread, then send updated banking details for a legitimate pending invoice. The company pays the correct invoice amount — but to the attackers' account.

    Variant 3 — Payroll Diversion:

    HR receives a convincing email from an employee asking to update their direct deposit details. The next payroll goes to the attacker.

    2024–2026 Evolution — Deepfake Video & Audio:

    In early 2024, a Hong Kong finance worker was tricked into transferring $25 million after attending a video call with deepfake versions of his CFO and colleagues. AI-generated voice and video are now being used in BEC attacks to bypass skepticism.

    Real Examples

  • FACC AG (Austria, 2016): The aerospace supplier lost €50 million in a BEC attack impersonating the CEO — one of the largest known BEC losses in Europe.
  • Toyota Boshoku (2019): A BEC attack via a spoofed partner email caused a $37 million wire transfer fraud.
  • Hong Kong multinational (2024): $25 million transferred after a deepfake video call impersonating the CFO.
  • The German Bundeskriminalamt (BKA) reports CEO fraud losses of tens of millions of euros per year across German-speaking countries.
  • Red Flags

  • An executive email asking for urgent, confidential wire transfers — especially outside normal approval processes.
  • Requests to change a supplier's or employee's banking details via email alone.
  • "Do not tell anyone" or "this is time-sensitive" pressure combined with a financial request.
  • Slight differences in the sender's email domain (e.g., company-name.net instead of company-name.com).
  • A trusted contact's email account suddenly using different writing style or unusual timing.
  • How to Protect Yourself

    • Always verify wire transfer requests or banking detail changes via a separate channel (phone call to a known number) — never rely solely on email confirmation
    • Implement a two-person rule for all outgoing wire transfers above a set threshold
    • Train finance and HR staff specifically on BEC patterns — attackers exploit urgency and authority
    • Enable DMARC, DKIM, and SPF on your company email domain to make spoofing much harder
    • Use email security tools that flag external emails impersonating internal executive names or domains

    What to Do If Affected

    1. 1.If you suspect a fraudulent transfer was made, call your bank immediately — there is a narrow window (often under 24 hours) to attempt a recall
    2. 2.Report to your national cybercrime authority and FBI IC3 (ic3.gov) if in the US — swift reporting improves recovery chances
    3. 3.Preserve all emails, headers, and communication logs as evidence
    4. 4.Conduct an internal review to find how attackers obtained information (compromised inbox, LinkedIn research, supplier breach)
    5. 5.Notify your cyber insurance provider immediately — most BEC losses are covered only if reported within a specific timeframe
    #BEC#CEO fraud#wire transfer#invoice fraud#email spoofing#deepfake#business